MailPoet – Newsletters, Email Marketing, and Automation <= 5.40.0 - Unauthenticated Authentication Bypass via Brute-Forceable Subscriber Link Tokens

Medium 4.8 CWE-330Fixed in 5.41.0
ID
WPSEC-2026-0499
Plugin
MailPoet – Newsletters, Email Marketing, and Automation (mailpoet)
Affected
all versions before 5.41.0
Remediation
Update to 5.41.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-330
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-07
Attack surface
MailPoet – Newsletters, Email Marketing, and Automation on WPSec AttackSurface
Fix released
Published

Description

The MailPoet plugin for WordPress is vulnerable to Authentication Bypass via subscriber link tokens in all versions up to, and including, 5.40.0. This is due to subscribers that are not given a random token when created, such as those added by the WordPress Users and WooCommerce Customers list synchronization, receiving a token of only six hexadecimal characters derived from the site's AUTH_KEY and the subscriber's email address, leaving roughly 16.7 million possible values. This makes it possible for unauthenticated attackers who know such a subscriber's email address to brute-force the token against the public subscription pages and then view and change that subscriber's subscription details and list memberships, unsubscribe them, or confirm a pending subscription on their behalf.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0